Threat intelligence
A threat intelligence workflow for CSIRTs
A traceable intelligence record with a named recipient, confidence assessment, sharing boundary and next action.
An independent tool index
for incident response teams
Practical incident response workflows, from the first input to a handoff another responder can use.
Each guide follows a specific job: what to prepare, what to check, what to hand over and which documented tool roles to evaluate. Use the steps to shape a pilot or improve an existing process.
These are editorial workflows supported by primary documentation. They are not a tested reference architecture. Follow the sources for product details and confirm compatibility in your own environment.
Threat intelligence
A traceable intelligence record with a named recipient, confidence assessment, sharing boundary and next action.
Feed automation
A monitored delivery path whose operator can account for accepted, rejected, delayed and delivered records.
Detection and monitoring
A versioned detection with validated data requirements, test results and an analyst response path.
Response coordination
A case another responder can take over without reconstructing the investigation from chat.
Malware analysis
A sample record linked to its origin, analysis results, confidence and a clear response or escalation decision.
Exposure discovery
A validated finding with an affected asset, accountable owner, action and recorded verification result.
Digital forensics
A reproducible analysis package with acquisition details, findings, a timeline and documented evidence gaps.
Compare the recorded deployment, license and origin facts. Check the source evidence before committing to a tool or integration.
Explore the tool index